← All CVEs

CVE-2014-0683

high · 10

The web management interface on the Cisco RV110W firewall with firmware 1.2.0.9 and earlier, RV215W router with firmware 1.1.0.5 and earlier, and CVR100W router with firmware 1.0.1.19 and earlier does not prevent replaying of modified authentication requests, which allows remote attackers to obtain administrative access by leveraging the ability to intercept requests, aka Bug IDs CSCul94527, CSCum86264, and CSCum86275.

10
CVSS
10.4%
EPSS (exploit prob.)
96th
EPSS percentile
2014-03-06
Published

AV:N/AC:L/Au:N/C:C/I:C/A:C

Weaknesses

CWE-255

Affected products

VendorProductAffected versions
ciscorv110w_firmware<= 1.2.0.9
ciscorv110wall versions
ciscorv215w_firmware<= 1.1.0.5
ciscorv215wall versions
ciscocvr100w_firmware<= 1.0.1.19
ciscocvr100wall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2014-0683